common possibilities are :
u visit some malicious site, it sends a trojan in ur temp internet file, which in turn donwloads and installs the malware wthout ur knowledge.
u install some somtware saying yes yes yes to everything, without reading the small print, and then say, 'hey iv got spyware' !
to kya kare ?
simple..this is what ive done.
replaced my host file (*www.mvps.org/winhelp2002/hosts.htm)
added spware sites to my restricted sites zone ('ie-spyads')
used the 'computer security tool'
and use ms antispyware and spywaredoctor.